Apache httpd 2.4.25 fixes some security-related bugs: https://httpd.apache.org/security/vulnerabilities_24.html
Specifically, please note the fix for CVE-2016-8743, which introduces some incompatible changes in how Apache httpd enforces HTTP request grammar. Leo Famulari (1): gnu: httpd: Update to 2.4.25 [fixes CVE-2016-{0736,2161,5387,8743}]. gnu/local.mk | 1 - gnu/packages/patches/httpd-CVE-2016-8740.patch | 36 -------------------------- gnu/packages/web.scm | 6 ++--- 3 files changed, 2 insertions(+), 41 deletions(-) delete mode 100644 gnu/packages/patches/httpd-CVE-2016-8740.patch -- 2.11.0